Talk With an Expert

Blind Data Exfiltration Using DNS and Burp Collaborator

  • Thu, Jan 12, 2023
  • 3:00PM - 4:00PM UTC
  • English
  • Eric Conrad
  • Technical Presentation
Webcast Hero

DNS provides one of the best methods for command and control, covert tunneling, and blind data exfiltration. Burp Collaborator provides a great way to both confirm blind injection, and also exfiltrate data. Penetration testers may prepend names to each DNS request, allowing data exfiltration subject to DNS's length limitations (63 characters per label, 255 characters total name) and character limitations. This webcast will describe methods for blind data exfiltration using Burp Collaborator (using both public and private servers), as well as using DNS without Burp. Content directly from SEC542: Web App Penetration Testing and Ethical Hacking.

Meet the speaker

Eric Conrad
Eric Conrad

Eric Conrad

President

Eric Conrad, a SANS Faculty Fellow and course author, has 28 years of information security experience. Eric is the CTO of Backshore Communications and his specialties include Intrusion Detection, Threat Hunting, and Penetration Testing.

Read more about Eric Conrad